Company POPIA Policy
POPIA is the Protection of Personal Information Act
As a law firm we will collect and utilise personal information of clients for whom we will perform legal services.
This policy sets out our collection, processing, storage and destruction process of personal information in order to protect data privacy rights and ensure compliance.
- Company Commitment and Scope:
We are committed to upholding the right to privacy of employees and clients alike.
- Definition of Personal Information:
Personal data will be information such as:
- General information:
Identity numbers/passport numbers, email addresses, employment details, contact details, financial history, banking details, SARS number.
- Special personal information:
Biometrics, race, gender, criminal record, tax status.
- Purpose of collection:
We will collect client information for purposes of verification of personal identity and for that of a legal entity all its beneficial owners’ details (“KYC” Know Your Client), legal compliance, billing purposes, legal obligations of the company which processing is mandated by the South African law(example FICA, Legal privileges, court rules) legitimate interests of the company, the client or third parties.
- Commitment to the 8 conditions of lawful processing:
- Accountability – we will comply with POPIA and all other legal and regulatory prescripts from start to finish of a matter and thereafter, till destruction of a file.
- Processing limitation – gathering only the necessary data and processing it for the purpose it was given to us with clear justification or direct consent.
- Purpose specification – documenting the explicit, legitimate reasons for which the data is captured. It will be the instruction we are attending to.
- Further processing limitation – ensure data is not repurposed for something incompatible with the original collection reason.
- Information quality – layout the steps to keep records accurate, complete and regularly updated. A client is required to update any change in legal status or contact details within 7 days of such change occurring. Re-verification of information already supplied may be requested at any time during a matter.
- Openness – remaining transparent about what information is collected, who collected it and why. We will ask a client for information directly.
- Securities safeguard – detailing the technical and physical systems used to avoid loss, unauthorized access or destruction. We use firewalls, anti-virus protection, secured cloud storage facilities, password protection, licensing and encryption safeguards, all set up to ensure there is no unauthorized access to private information. Sharing of information will occur on bank platforms for related instructions, SARS for obtaining clearances or assessments, The Master of the High Court for related matters, Deeds Office, courts for litigation purposes, attorneys acting as correspondents, advocates representing clients, the FIC(Financial Intelligence Centre)for legislative compliancy issues where applicable and in terms of any court order. This list may not be fully comprehensive.
- Data subject participation – outlining the right to individuals to request access to or deletion of their files. We will not keep personal information
longer than necessary. According to law closed files are to be kept for 7
(seven) years. The firm adheres to statutory retention periods. Once expired, the records are shredded, deleted or de-identified securely.
- Data Subject rights:
A client has the right to:
- Request access to records, not yet destroyed,
- Request correction or deletion of in-accurate irrelevant or excessive information,
- Object to the processing of their personal information.
- Cross-border transfer of information and third party operators:
Personal information will only be transferred across borders if the receiving country has similar data protection laws or with explicit client instructions to do so written or consent by client.
Where we use correspondents and advocates (third -party operators) we will ensure they comply with POPIA.
- Breach notification:
In the event of a suspected or actual data breach, the information regulator and affected data subjects will be notified thereof as soon as reasonably possible allowing clients the opportunity to take necessary protective measures.
- Disciplinary action:
Wilful mismanagement, gross negligence, or failure to comply with this policy is considered serious misconduct and may result in disciplinary action, including dismissal.
- Information offer:
The firm’s information officer is Charmaine Krause.
Contact number: 011 815 3255 / 082 554 3301
Email address: ckrause@mkninc.co.za also copy : admin@mkninc.co.za
JUNE 2026

